Discrezo Trust Center

Trust should be inspectable.

Discrezo is built around a simple idea: no single party should need both your identity and your AI conversation. This Trust Center explains the architecture, controls and independent assurance behind that claim.

See what we know. What AI providers receive. What is encrypted. What has been independently certified. And where work is still in progress.

ISO/IEC 27001 certified

You

Who you are

Account

  • Account
  • Subscription
  • Billing
Separated

What you ask

AI inference

  • Prompt
  • Context
  • Response

Encrypted history

Ciphertext only on Discrezo servers.

Nobody needs the whole picture.

At a glance

What you should know before you trust us.

ISO/IEC 27001

Certified

Discrezo operates an ISO/IEC 27001-certified information security management system.

Account ↔ inference

Separated by design

The AI inference path does not need your Discrezo account identity to answer a request.

Saved history

Encrypted before sync

Discrezo's backend does not hold the key required to read your saved conversation content.

Standard Mode

Identity separation

The AI provider receives the prompt and context needed to answer it without needing your Discrezo account identity attached.

Private Mode

Open-model routes only

Private Mode excludes OpenAI, Anthropic and Google from eligible prompt-processing routes.

Product security review

Scheduled

A product-specific independent security review is part of the launch programme and must not be described as complete until it is complete.

Privacy architecture

Different systems are allowed to know different things.

Discrezo does not rely on everyone inside one giant system promising not to look. The architecture gives different responsibilities to different parts of the service.

Account

Who

Can process

  • Email
  • Account
  • Subscription
  • Billing relationship
  • Plan entitlement

Does not need

  • Readable AI conversations

Inference

What

Can process

  • Prompt
  • Relevant context
  • Selected route
  • Generated response

Does not need

  • Account email
  • Payment identity
  • Discrezo customer identity

Encrypted sync

History

Can hold

  • Encrypted conversations
  • Encrypted memory

Does not have

  • The key required to read them

Each side gets what it needs. Nobody needs everything.

Important

Identity separation does not hide the words you type.

In Standard Mode, the AI provider processing your request can read the prompt and relevant context. If you type your name, employer, address or other identifying information into the prompt, the provider can read those words.

We separate your Discrezo identity from the request. We do not pretend the question itself is invisible.

Security

Security protects the privacy boundary.

The privacy model only works if the systems preserving it remain secure.

Credentials

Provider credentials stay server-side.

Credentials used to access AI providers are held within protected server-side systems and are not exposed to ordinary user browsers.

Access

Access follows responsibility.

Different systems and personnel should only receive the access required for their job.

Logging

A debugging system should not become a conversation archive.

Prompt and response bodies are designed to be excluded from ordinary inference logs.

Software

Privacy boundaries are treated as testable requirements.

Security checks include controls around secrets, dependencies and important privacy boundaries.

Incidents

Have the process before the problem.

Discrezo maintains incident-management processes for identifying, containing, investigating and responding to security events.

Independent assurance

Don't take every claim from us.

Certified

ISO/IEC 27001 certified.

Discrezo operates an independently certified information security management system under ISO/IEC 27001.

ISO 27001 provides a formal framework for identifying security risks, assigning controls, managing incidents, governing access and continually improving information security.

Certification validates the information-security management system within its certified scope. It does not mean every individual Discrezo product claim has automatically been independently penetration-tested.

Scheduled

Discrezo architecture review.

A separate product-specific independent security review is scheduled as part of the launch programme.

This review is intended to examine critical Discrezo-specific security and privacy boundaries.

It is not yet complete.

Certified where certified. In progress where in progress.

Future assurance

Further assurance will be listed here as it is completed. Areas we expect to cover include product security assessment, penetration testing, additional certifications, privacy architecture review, audit reports and transparency reporting. None of these are complete today, so none of them are listed as evidence.

AI providers

The model gets the question. It doesn't need your Discrezo account.

Standard Mode provider receives

  • Prompt
  • Relevant context
  • Information necessary to generate the response

Standard Mode provider does not need

  • Discrezo account ID
  • Discrezo account email
  • Payment identity
  • Originating network identity

The words inside your prompt can still identify you if you put identifying information there.

A good model is not automatically an approved model.

Discrezo considers more than model quality when determining which routes are eligible. Privacy, security, availability and the user's selected mode also matter.

Quality

Is the model capable of answering the task?

Privacy

Does the route satisfy the privacy requirements of the selected mode?

Security

Is the provider configuration approved?

Availability

Is the route healthy enough to use?

Security constraints come before model preference.

Private Mode

When you exclude Big AI, the router cannot quietly put it back.

Private Mode restricts eligible prompt processing to supported open-model routes. Requests are not intentionally routed to OpenAI, Anthropic or Google.

Hard routing constraint

Provider eligibility is restricted before ordinary model selection.

No silent fallback

An excluded provider should not be used simply because it would otherwise provide a stronger answer.

Honest trade-off

Restricting model choice may affect performance on particularly difficult tasks.

Private means the privacy rule wins.

Your data

Stored does not mean readable.

Discrezo does not say “nothing is stored”. Saved conversation history may need to be stored so that it can sync between devices. The important question is what form that data takes and who can read it.

Your trusted device

Readable conversation

Encrypted before sync

Discrezo storage

Encrypted data

No backend decryption key

You can read your history. Discrezo cannot.

Discrezo may still observe limited information associated with storage and synchronisation, such as that encrypted data exists or that a sync occurred. Encryption does not make all metadata disappear.

Two types of keys

Service credentials

Used by Discrezo to access AI providers.

Protected server-side.

Conversation key

Used to read your saved conversation history.

Held by your trusted devices, not Discrezo's backend.

The key that lets us pay an AI provider belongs on our infrastructure. The key that lets someone read your history does not.

Observability

Know whether the system works without reading what you said.

Operational information

  • Provider and route health
  • Latency
  • Token or compute volume
  • Error category
  • Service availability

Conversation content

Not intended for ordinary inference logs:

  • Prompt body
  • Response body
  • Readable conversation history
  • Account identity attached to inference logs

The safest unnecessary field is one that was never collected.

Software security

Security starts before deployment.

Threat modelling

We identify ways privacy boundaries could fail before relying on them.

Relevant threat categories may include

  • Account-to-prompt correlation
  • Metadata leakage
  • Logging leakage
  • Credential compromise
  • Malicious routing inputs
  • Client compromise
  • Supply-chain risk

The internal threat model itself is not published.

Security checks

Software changes are checked for issues such as exposed secrets, vulnerable dependencies and violations of important privacy boundaries.

Human review

Automated checks support engineering review. They do not replace security judgement.

Router safety

A prompt can influence which eligible model is appropriate. It cannot give itself permission to override the user's privacy mode.

Operations

Security has to survive day-to-day operation.

Access control

Access is restricted according to role and need.

Security monitoring

Operational systems are monitored for failures and security events.

Incident response

Processes exist for containment, investigation and remediation.

Provider control

Problematic provider routes or credentials can be restricted where necessary.

Transparency

Tell people what is true. Especially when the answer is uncomfortable.

What we can read

Account information

Yes.

Discrezo needs account information to operate your subscription.

Saved conversation history

No readable copy.

There is no readable copy on Discrezo's backend where encrypted history is operating as designed.

Standard Mode prompt

Processed to answer it.

Processed by the inference path and the AI provider necessary to answer it.

Private Mode prompt

Eligible routes only.

Processed only through eligible Private Mode routes.

What we do not claim

We do not claim.

“Nothing is stored.”

Because encrypted history may be stored.

“AI providers cannot see your prompt.”

Because the AI answering a Standard Mode request needs to process it.

“Discrezo doesn’t know who you are.”

Because the account side needs to know who has an account and subscription.

“Private Mode means no external computer processes the prompt.”

Because infrastructure is still required to run eligible open models.

“Discrezo is unhackable.”

No responsible software company should say that.

“ISO 27001 proves every product claim.”

It does not.

Precise claims are stronger than bigger claims.

Legal requests

We can only provide what we have.

Like other companies, Discrezo is subject to valid legal process. But there is an important difference between data stored by a system and information that system has the technical ability to read.

Account information

If lawfully required and available to Discrezo, this may be capable of disclosure.

Encrypted history

If Discrezo does not possess the key required to decrypt saved conversation data, receiving a legal demand does not create that key.

We do not claim that legal requests can never result in disclosure. We describe what the architecture actually allows us to access.

Transparency reporting.

Planned

As Discrezo grows, we intend to publish appropriate information about legal requests and other matters relevant to user trust where doing so is lawful and meaningful.

Security research

Good security welcomes scrutiny.

Security concerns can currently be reported to support@discrezo.com while our dedicated vulnerability disclosure process is being established.

Disclosure programme in development

Current status

Where we actually stand.

ISO/IEC 27001

Certified

Independent assurance over Discrezo's information-security management system within its certified scope.

Identity / inference separation

Architectural control

Built into the product design.

Encrypted conversation sync

Launch requirement

Saved conversation data is designed to be encrypted before sync with no backend-held decryption key.

Privacy-boundary automated tests

Launch requirement

Tests designed to protect critical architecture boundaries.

Provider privacy configuration verification

Launch requirement

Routes must satisfy required provider configuration before launch.

Product-specific independent security review

Scheduled

Separate from ISO/IEC 27001 certification.

Public transparency reporting

Planned

Not published today. It will only appear here once it exists.

Vulnerability disclosure programme

In development

Security reports can be sent to support@discrezo.com in the meantime.

Our principles

The standards we design around.

Separate

Do not put identity and readable AI activity together when the product does not require it.

Minimise

Do not give a system information it does not need.

Encrypt

Keep saved conversation content unreadable to infrastructure that only needs to store it.

Verify

Test important boundaries and seek external scrutiny rather than relying only on internal confidence.

What we are building

Better AI should not require giving one company the whole picture.

Automatic routing

Different tasks can be handled by different eligible models without requiring users to understand model selection.

Privacy-aware routing

The privacy mode constrains which models are eligible before normal model selection.

Encrypted memory

Personalisation should not require the backend to own a readable archive of someone's AI history.

Provider independence

Users should not need to build their entire AI life inside one model provider's account.

Our position

AI privacy should not be a specialist feature.

People increasingly use AI for work, relationships, ideas, finances, health questions and decisions they may never type into a public search engine. Privacy should therefore be part of the default architecture, not an expensive enterprise add-on.

That is why core Discrezo privacy protections are included across the Individual, Pro, Researcher and Business experience rather than reserved only for the highest-priced plan.

FAQ

Trust questions.

Saved conversation history is designed to be encrypted before sync, with Discrezo's backend not holding the key required to decrypt it. During a live request, the inference systems necessarily process the request so it can be routed and answered.

Trust, earned

Don't trust the slogan. Inspect the system.

Read the architecture. Check the limits. See what has been independently certified. Watch what changes.

Privacy is the architecture. Security keeps it true. Transparency lets you verify it.